Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-58138

Orkes Conductor unauthenticated RCE via inline workflow definitions

Unauthenticated RCE in Orkes Conductor via crafted inline workflow definitions. CVSS 9.8 critical; active exploitation confirmed.

cat cve-2026-58138.json
Vendor
Orkes
Product
Orkes Conductor
CVSS
9.8
EPSS (exploit probability)
9.3%
Status
exploited-in-wild
Published

An unauthenticated attacker can execute arbitrary code on Orkes Conductor servers by submitting crafted inline workflow definitions to the API. No authentication is required to trigger the flaw.

Active exploitation was confirmed by SecurityWeek as of September 17, 2026. Refer to the NVD entry and the Orkes security advisory for specific affected version ranges and available patches. If a patch is not yet available in your environment, restrict network access to the Conductor API to trusted sources and treat any anomalous workflow execution as a potential incident.